Received a Password Reset Email But Didn't Request One: How to Secure Your Account

 / 
3

Your phone lights up at 3 a.m. with a new email alert: "You have successfully reset your login password. If this was not you, click here to cancel." You jolt awake and your first instinct is to tap that "cancel" button.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

Do NOT click it. Tapping any link or button in this email right now could hand full control of your account over to scammers.

This is not a regular spam email, it is a clear signal that someone is actively trying to access your account. Stay calm, and follow the steps below to secure it.

Step 1: Take Urgent Action First — Block the Attacker From Logging In

Goal: Lock down full control of your account before the attacker can get the new password.

What to do: Close the email immediately, and do not click any buttons or links inside it. Open the official mobile app directly (do not use any web page redirected from the email), or manually type the official exchange website address into your browser to log into your account.

Completion check: You successfully log in with your original password. If you can log in normally, it means the attacker has not finished the password reset process yet.

Actions after logging in (follow priority order):

  1. Change your login password right away. Go to your account security settings, set a completely new password different from your old one, at least 12 characters long, with a mix of uppercase and lowercase letters, numbers and symbols.

  2. Force all logged-in devices to log out. Find "Device Management" or "Login History" in security settings, tap "Log out all devices" or "End all active sessions". This will immediately invalidate every existing login session for your account.

  3. Check and reset your 2-factor authentication (2FA). Head to the security center to confirm your Google Authenticator or SMS verification still belongs to you. If you suspect any leak risk, directly reset 2FA and bind it to a new device.

Completion check: You can log in successfully with the new password, only your current device shows up in the device list, and 2FA works normally.

Step 2: Verify the Email to Confirm If a Real Reset Attempt Happened

Goal: Figure out if the email is a real password reset request, or a pure phishing scam.

There are two possible scenarios, handle them as instructed below:

Scenario A: The email sender address uses the official domain (for example @binance.com), and it has a button that says "If this was not you, click here to cancel"

This is proof that someone is actually trying to reset your password. It means the attacker already knows your account (email address), and is using the "Forgot Password" function to launch a reset request.

What to do: Do not perform any operations inside the email. Open the official app or manually enter the website to log in, then immediately follow the process in Step 1 to change your password, log out all devices, and reset 2FA.

Scenario B: The email asks you to "Click here to cancel reset" but the sender address looks suspicious (has extra letters, uses a free public email service, etc.)

This is a phishing email, designed to trick you into clicking the "cancel" button. The fake page you are redirected to will ask you to enter your account password and even verification codes, and you will give away full access to your account the moment you input those details.

What to do: Directly mark it as spam and delete it. Then open your official app and log in to double check that your account is in normal status. No extra operations are needed, but stay alert.

Completion check: You can clearly confirm which scenario the email falls into, and have finished the corresponding required actions.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

Step 3: Check for Hidden Backdoors in Your Account

Goal: Find out if the attacker has set up any persistent access channel in your account.

What to do: After logging into your account, go to the "API Management" or "API Keys" page, check for any API keys that you did not create recently. If you find any unknown keys, revoke them immediately.

Then go to the "Withdrawal Address Management" or "Whitelist Address" page, check if any new unknown withdrawal addresses have been added.

Completion check: Only the API keys you personally confirmed are in the API list, and there are no strange unrecognized addresses in the withdrawal whitelist.

Risk Reminder: A common attack trick is that attackers will not log in right after triggering the password reset email, but wait for you to click the "cancel reset" link in the email. That link leads to a fake lookalike page, and once you enter your account credentials, the attacker can steal them to log in. So never access your account from links in emails, always open the official app or type the website address manually.

Verification after all operations: You can log in successfully with the new password, only your current device is in the device list, and the API and withdrawal address lists are fully clean. Then keep an eye out for any abnormal login attempt notifications in the next 24 to 48 hours.

Next steps: Go to your crypto exchange's security center, take a screenshot of the "Login Device Management" page for backup. Turn on "Login Alert" or "Security Notification" settings, so you will get a notice every time a new device tries to log into your account. If you have not set up an anti-phishing code yet, set one up right now — it will act as your final line of defense to tell real official emails from fake scam ones.